You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

跨域Kerberos认证下Spark YARN集群模式访问HDFS失败排查

解决Spark YARN-Cluster模式跨域Kerberos HDFS写入失败的问题

看起来你碰到的问题很典型:跨域Kerberos集群下,Spark本地模式能正常写远端HDFS,但YARN-Cluster模式就掉链子,核心原因是YARN Cluster模式下Driver/Executor的认证上下文和本地模式完全不同——本地模式直接用你当前会话的Kerberos缓存,但YARN里的Driver是由NodeManager启动的,默认会依赖YARN的令牌委托机制,而这个机制对跨域HDFS并不生效,导致FileSystem被迫用SIMPLE认证。

结合你的场景(MIT KDC跨域+Ranger,DistCP正常),我给你梳理几个关键的排查和修复步骤:

1. 确保跨域HDFS配置能被Spark Driver/Executor加载

YARN Cluster模式下,Driver运行在NodeManager节点上,不会自动读取你本地的Hadoop配置文件。你需要明确把集群B的core-site.xml和hdfs-site.xml传递给Spark:

  • 提交命令中添加--files /path/to/clusterB/core-site.xml,/path/to/clusterB/hdfs-site.xml
  • 同时通过--conf指定Spark使用这些配置:
    --conf spark.hadoop.fs.defaultFS=hdfs://clusterB-nn:8020 \
    --conf spark.hadoop.hadoop.security.authentication=kerberos \
    --conf spark.hadoop.hdfs.namenode.kerberos.principal=nn/_HOST@CLUSTERB.REALM
    

2. 强制Spark在YARN中使用Kerberos认证而非YARN令牌

YARN的Delegation Token只对本地集群有效,跨域HDFS无法识别它。所以需要让Spark的Driver和Executor直接用Kerberos keytab重新认证:

  • 提交命令中添加以下配置(替换成你的集群A主体和keytab):
    --conf spark.driver.user.principal=your-spark-principal@CLUSTERA.REALM \
    --conf spark.driver.user.keytab=/path/to/your-principal.keytab \
    --conf spark.executor.user.principal=your-spark-principal@CLUSTERA.REALM \
    --conf spark.executor.user.keytab=/path/to/your-principal.keytab \
    --files /path/to/your-principal.keytab
    
  • 同时禁用YARN对HDFS凭据的自动获取(避免冲突):
    --conf spark.yarn.security.credentials.hdfs.enabled=false
    

3. 验证跨域主体的权限和KDC信任

虽然DistCP正常,但还是要确认:

  • 集群A的主体your-spark-principal@CLUSTERA.REALM在集群B的KDC中被信任(MIT KDC的跨域信任配置正确)
  • Ranger中已经给这个主体配置了集群B HDFS的写入权限
  • 集群B的hdfs-site.xml中Kerberos认证配置正常,且Ranger的权限规则已正确生效

4. 调试验证步骤

如果还是有问题,建议在Spark代码中添加调试日志,打印FileSystem的配置:

import org.apache.hadoop.fs.FileSystem
import org.apache.hadoop.conf.Configuration
import java.net.URI

val conf = new Configuration()
val fs = FileSystem.get(new URI("hdfs://clusterB-nn:8020"), conf)
println(s"Authentication method: ${conf.get("hadoop.security.authentication")}")
println(s"FS User: ${fs.getScheme()}://${fs.getUri().getAuthority()} - ${fs.getOwner()}")

然后查看YARN的Driver日志,确认认证方式是不是KERBEROS,用户主体是不是正确的。另外,检查YARN NodeManager日志,看Driver启动时有没有加载keytab的相关日志,有没有Kerberos认证失败的细节。


内容的提问来源于stack exchange,提问作者Pramod GM

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 10:03:30